# Filebeat syslog fields are missing in Kibana

**URL:** https://discuss.elastic.co/t/filebeat-syslog-fields-are-missing-in-kibana/128923
**Category:** Beats
**Tags:** filebeat
**Created:** [April 20, 2018, 6:14pm UTC](https://discuss.elastic.co/t/filebeat-syslog-fields-are-missing-in-kibana/128923 "2018-04-20T18:14:56Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![yan](https://avatars.discourse-cdn.com/v4/letter/y/3e96dc/32.png) [@yan](https://discuss.elastic.co/u/yan)
#### Post date: [April 20, 2018, 6:14pm UTC](https://discuss.elastic.co/t/filebeat-syslog-fields-are-missing-in-kibana/128923/1 "2018-04-20T18:14:56Z")

</div>

Hi,

I am running ELK 6.2.4 (Elasticsearch, Kibana and Filebeat) on Centos 7. I see all the logs from /var/log/messages in Kibana "Discover" window, BUT for some reason the syslog fields are missing in the "available fields" list. Can you please point on a possible reason for that ?

I can supply any needed information, when in general I can say that all was configured by the book including:

1. enabling system module
2. filebeat setup
3. ingest-geoip plugin installation

Looks like there is something basic that I am missing.

- Please note that when running ELK on Ubuntu everything worked fine.

I will highly appreciate you assistance.

Thanks,  
Yan

---

<div class="post-metadata">

### Author: ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)
#### Post date: [April 27, 2018, 1:47pm UTC](https://discuss.elastic.co/t/filebeat-syslog-fields-are-missing-in-kibana/128923/2 "2018-04-27T13:47:48Z")

</div>

It might be that the field list in the Kibana index pattern needs to be updated. I would first try going to the management app (on the left nav) then clicking on "Index Patterns" under the Kibana subhead. From there click on the name of the index pattern. You should see a group of buttons in the top right hand corner of the screen that looks like:

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77b42e136d377d89cd294c8f79e949a744c43a0f.png)

Click the middle button to "refresh" the fields for that index pattern.

---

<div class="post-metadata">

### Author: ![yan](https://avatars.discourse-cdn.com/v4/letter/y/3e96dc/32.png) [@yan](https://discuss.elastic.co/u/yan)
#### Post date: [April 29, 2018, 9:46am UTC](https://discuss.elastic.co/t/filebeat-syslog-fields-are-missing-in-kibana/128923/3 "2018-04-29T09:46:53Z")

</div>

Ok, I tried that and got the following error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/2/022cfa6dfdd31eb7fc1e80351bd7d394c9537f7c.png)

Any idea what this is about ?

Thanks

---

<div class="post-metadata">

### Author: ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)
#### Post date: [April 30, 2018, 3:13pm UTC](https://discuss.elastic.co/t/filebeat-syslog-fields-are-missing-in-kibana/128923/4 "2018-04-30T15:13:17Z")

</div>

It looks like you're `.kibana` index is either "Read Only" or you don't have write permissions.

---

<div class="post-metadata">

### Author: ![yan](https://avatars.discourse-cdn.com/v4/letter/y/3e96dc/32.png) [@yan](https://discuss.elastic.co/u/yan)
#### Post date: [May 1, 2018, 11:50am UTC](https://discuss.elastic.co/t/filebeat-syslog-fields-are-missing-in-kibana/128923/5 "2018-05-01T11:50:27Z")

</div>

Ok, I restarted the ELK and eventually managed to do "refresh" per your example above without any errors, but the problem remains. syslog fields are not there.

I am open for any further suggestions.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 29, 2018, 11:50am UTC](https://discuss.elastic.co/t/filebeat-syslog-fields-are-missing-in-kibana/128923/6 "2018-05-29T11:50:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
